styx
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's financial capabilities match its stated BTC→sBTC bridge purpose, but it carries high inherent risk because it can autonomously move funds and depends on a not-fully-verifiable Styx SDK/backend, with evidence of a Vercel-hosted intermediary and a pre-configured API key. This looks more like a risky DeFi transaction skill than confirmed malware.
Confidence: 84%Severity: 81%
Audit Metadata